CVE-2026-67104

medium

Description

HCL BigFix Service Management is affected by an Information Disclosure vulnerability, which could allow an unauthenticated attacker to analyze publicly accessible JavaScript files, enabling the discovery of hidden administrative API endpoints for further targeted exploitation.

References

https://support.hcl-software.com/csm?id=kb_article&sysparm_article=KB0134015

https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-90877

Details

Source: Mitre, NVD

Published: 2026-10-01

Updated: 2026-10-05

Risk Information

CVSS v2

Base Score: 5

Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:N/A:N

Severity: Medium

CVSS v3

Base Score: 5.3

Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

Severity: Medium

EPSS

EPSS: 0.00235